Ernst and Young says client tax documents were stolen from a support platform
Ernst & Young is notifying clients of a breach at a third-party IT service management platform used by staff supporting its tax practice. Support tickets submitted through the platform could include attached documents containing client tax information, and the firm says an unauthorized third party accessed the platform between March 28 and April 12 and downloaded documents belonging to a number of clients. EY detected the activity on April 23, roughly two weeks after it stopped, and filed breach notifications with the California Attorney General in July. The exposed data includes personal and financial information used to prepare tax filings.
- Check
- EY tax clients should watch for a notification letter, monitor financial accounts and credit, and treat unexpected messages referencing their tax filings or the firm as likely phishing.
- Affected
- EY tax clients whose documents were attached to support tickets; personal and financial information used to prepare tax filings was downloaded, which supports identity theft and convincing targeted phishing.
- Fix
- Affected clients should consider a credit freeze and monitor accounts. Organizations should limit what sensitive data staff attach to helpdesk tickets, set retention limits on attachments, and assess vendor security.